Coldcard Hack Exposes Flaw in Hardware Wallet Security
A recent hack of the Coldcard wallet has resulted in the theft of approximately $116 million worth of BTC, making it one of the largest hardware wallet exploits on record. The attack exploited a flaw in the firmware that caused private keys to be predictable, allowing attackers to brute-force or precompute against wallets created between March 2021 and July 31, 2026.
The first signs of trouble surfaced on July 30, 2026, when roughly $38 million worth of BTC was drained from around 500 dormant wallets. Over the next five days, three more waves of theft pushed total losses to over $116 million, affecting more than 5,200 addresses.
Coldcard devices ship with a dedicated hardware random number generator chip specifically so that entropy doesn’t depend on a predictable software routine. However, the vulnerability caused the device to bypass its dedicated hardware randomness chip during key generation, instead using a predictable software substitute, resulting in a collapse in effective entropy.
The attack has raised concerns about the security of self-custody wallets and highlighted the importance of robust random number generation in preventing such exploits.